Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9m57-5mv3-fjx3

Опубликовано: 13 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.6

Описание

Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthenticated attacker could create a malicious JNLP (Java Network Launch Protocol) file accessible by a public facing URL. When a victim clicks on the URL the accessed Wily Introscope Server could execute OS commands on the victim's machine. This could completely compromising confidentiality, integrity and availability of the system.

Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthenticated attacker could create a malicious JNLP (Java Network Launch Protocol) file accessible by a public facing URL. When a victim clicks on the URL the accessed Wily Introscope Server could execute OS commands on the victim's machine. This could completely compromising confidentiality, integrity and availability of the system.

EPSS

Процентиль: 22%
0.00074
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.6
nvd
27 дней назад

Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthenticated attacker could create a malicious JNLP (Java Network Launch Protocol) file accessible by a public facing URL. When a victim clicks on the URL the accessed Wily Introscope Server could execute OS commands on the victim's machine. This could completely compromising confidentiality, integrity and availability of the system.

CVSS3: 9.6
fstec
27 дней назад

Уязвимость приложения для углубленного анализа, создания пользовательских панелей мониторинга и детального изучения метрик Workstation сервера для сбора, хранения и отображения данных о производительности систем SAP SAP Wily Introscope Enterprise Manager (EM), позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 22%
0.00074
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-94